Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Architecture Professional

Domain 2Objective 2

2.2 Verify and Validate Design (e.g., Functional Acceptance Testing, Regression) ISSAP Practice Questions (Page 4)

Part of the Security Architecture Modeling domain, which accounts for 22% of the ISSAP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
5concepts
22%of the exam

Questions 16–20

  1. 16expert · hard

    A security architect is validating a new zero trust architecture. The threat model identified a gap: the design does not include continuous monitoring of user behavior. The architect is considering adding a user and entity behavior analytics (UEBA) solution or implementing periodic access reviews. The organization has a compliance requirement to detect anomalous behavior within 24 hours. The UEBA solution is expensive and requires significant integration effort. What should the architect do?

    Select an answer first
  2. 17foundation · easy

    A security architect is performing gap identification on a new system design. Which activity is most directly associated with this process?

    Select an answer first
  3. 18expert · hard

    A security architect is validating a new data loss prevention (DLP) solution. The threat model identified a gap: the design does not cover data exfiltration via email. The architect is considering two mitigations: adding email inspection to the DLP solution or implementing a separate email security gateway. The organization has a limited budget and wants to minimize the number of vendors. Which mitigation should the architect choose?

    Select an answer first
  4. 19application · medium

    A development team is validating a new microservices-based payment system. The threat model identified a risk of using outdated third-party libraries with known vulnerabilities. The security architect must choose a code review methodology to validate that the implementation does not introduce this risk. Which methodology is most appropriate?

    Select an answer first
  5. 20expert · hard

    A security architect is validating a new IoT device management platform. The threat model identified a high-impact threat of unauthorized device takeover via a weak authentication mechanism. The design includes a proposed mitigation of certificate-based authentication. However, the threat model also shows that the certificate provisioning process is vulnerable to interception. The architect must decide how to validate the design. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSAP” is a trademark of its owner, used for identification only.